CRM-10Service / PSAAdministrator

How to Manage GDPR Consent for Leads in CrmLeaf

All editions. Core feature - no add-on required. GDPR configuration is an account-level settings area.

Part 2 · CRM and Clients6 min readIncludes a Service / PSA lens

Availability: All editions. Core feature - no add-on required. GDPR configuration is an account-level settings area.

Overview

CrmLeaf provides public consent pages for leads, so a prospect can record their consent on a page that requires no login, and an Administrator can then approve or reject what was submitted. Together with password-protected notes on lead and deal records, this gives you a documented way to handle consent and sensitive personal data in your CRM. This article covers the CrmLeaf mechanics; it is not legal advice on your obligations.

How It Works

A consent page is published for a lead at a public address. The lead submits their consent there, and the submission is reviewed by an Administrator, who approves or rejects it.

Configure GDPR settings Share the consent page Lead submits consent Administrator approves or rejects Record the outcome

  • Public lead consent pages are hosted at /consent/l/{hash}. The hash identifies the lead, so the page needs no login.
  • Submissions are reviewed by an Administrator, who can Approve or Reject them.
  • Consent can also be recorded per deal.
  • Notes on lead and deal records can be password-protected, so sensitive detail is not visible to everyone who can open the record.
  • Ownership-based visibility and organisation filtering continue to apply to the underlying lead and deal records.

Who Can Use This Feature?

Administrator

  • Configure the account's GDPR settings.
  • Share consent pages with leads.
  • Approve or reject submitted consent.
  • Decide which notes require password protection.

This functionality is available only to Administrators. Leads themselves complete the public consent page without a CrmLeaf login.

Prerequisites

  • Administrator access to the account.
  • Lead records for the people whose consent you are collecting.
  • Your own agreed consent wording and retention policy, decided before you publish anything.
  • A working outgoing mail configuration, if you intend to send consent page links by email.

For Administrators

Step 1: Configure the account's GDPR settings

What to do: Review and complete the GDPR configuration for your account before you collect any consent. Agree your wording with whoever is accountable for data protection in your organisation first, because the public page is what the prospect will rely on.

What to verify: Open a consent page and confirm the wording shown is the wording you approved.

What to do: Open the lead and share its public consent page. The page is reachable at /consent/l/{hash} and requires no login, so the prospect can complete it directly.

What to verify: The link opens the consent page for the correct lead.

What to do: Review each submission against your policy. Check that the person who submitted matches the lead and that the consent covers the processing you actually intend to carry out.

What to verify: The submission is attached to the correct lead record.

Step 4: Approve or reject the submission

What to do: Select Approve where the consent is valid and complete, or Reject where it is not. Treat rejection as a signal that the consent must be collected again, not as a way to hide a record.

What to verify: The consent status on the lead reflects your decision.

Step 5: Protect sensitive notes

What to do: Where a note contains sensitive personal or commercial detail, use a password-protected note instead of a normal one. Keep the number of protected notes small, and record separately who is entitled to open them.

What to verify: The protected note cannot be read without the password by someone who can otherwise open the record.

What to do: Review the public web-to-lead forms and imports that create leads, and make sure each capture route is covered by your consent process. A form that collects personal data without a consent step leaves a gap you will have to fill by hand later.

What to verify: Every documented capture route into your CRM has a defined consent step.

Expected Result

Consent pages are available at their public addresses, submissions from leads are recorded against the correct lead records, and each submission carries an Administrator decision of approved or rejected. Sensitive notes are password-protected.

Service / PSA lens

Service Organisation Context

Professional services firms routinely hold personal and commercially sensitive material about the people they are selling to — particularly in legal, advisory, recruitment-adjacent and HR consulting work — and are often asked to evidence how consent was obtained. Public consent pages let a prospect record consent without a login, and an Administrator approves or rejects each submission, so the decision is documented rather than remembered. Password-protected notes let a firm keep confidential detail off the screen of everyone who can open the record. This article describes the CrmLeaf mechanics only; the obligations that apply to your firm are a matter for your own advisers. The same consent handling applies across all editions.

Important Notes

  • Menu names and their position can differ between product editions and can be customised for your account, so your sidebar may not match these paths exactly. Use Search or your Quick Access items if you cannot find a screen.
  • This article describes CrmLeaf functionality only. Whether your consent wording, lawful basis and retention practice meet the rules that apply to you is a matter for your own data protection advisers.
  • The consent page is public and identified by a hash in the URL. Treat the link as sensitive and send it only to the person concerned.
  • Approval is a human decision. CrmLeaf records it, but does not judge whether the consent is legally sufficient.
  • Password-protected notes restrict who can read the content. Keep your own record of who holds the password.

Common Scenarios

Example: consent after an event. A team imports 60 badge scans from a trade show. Because the scans alone do not evidence consent for marketing contact, the Administrator sends each imported lead its consent page and approves only the submissions that come back.

Example: a sensitive negotiation. A deal involves commercially confidential pricing. The account manager records the detail in a password-protected note so colleagues who can see the deal cannot read the terms.

Troubleshooting

IssuePossible CauseResolution
The consent page does not open.The link was truncated or altered, so the hash no longer resolves to a lead.Copy the full consent page link again from the lead record and resend it.
A submission is not visible for review.You are working in a different organisation, or the lead is outside your visibility.Switch to the organisation holding the lead and confirm your access.
You cannot approve or reject.You are not signed in as an Administrator.Ask an Administrator to make the decision.
The consent wording is wrong on the public page.The GDPR settings have not been completed or updated.Update the GDPR settings and re-check the public page.
A colleague cannot read an important note.The note is password-protected.Share the password through your own approved channel, or move non-sensitive content to a normal note.

Frequently Asked Questions

No. The consent page is a public page identified by a hash in its address.

An Administrator. Approval and rejection are Administrator actions on the submitted consent.

Yes. Consent handling is documented for both leads and deals.

Does CrmLeaf make my account compliant with data protection law?

No. CrmLeaf provides consent pages, an approval step and password-protected notes. Compliance depends on your own policies, wording and practice.

Still need a hand?

Our support team answers on business days. Reference CRM-10 so we can jump straight in.